Skip to main content

Epona

The DMS question most law firms forget to ask

And why that question becomes a compliance problem later

Most DMS selection projects start with the same questions: Does it look modern? Is the user experience good? How strong is the search? How does email filing work? What about AI features, integrations, matter management, mobility? All reasonable questions, but the most important question is often ignored, even though it becomes decisive later. It is deceptively simple: under whose legal reach does your data fall?

“Data in Europe does not automatically mean legal control in Europe”

That sounds abstract until it becomes very concrete. Many vendors respond to privacy and compliance concerns by pointing to European hosting. Germany, Ireland, the EU, regional data centers; all neatly within geography that sounds safe. For many firms, that creates a sense of comfort, as if European hosting automatically solves the legal risk, but: it doesn’t.

Data in Europe does not automatically mean legal control in Europe. A vendor can host data in the EU and remain subject to U.S. jurisdiction. That is where the conversation about access, control, legal exposure, and accountability should start. For commercial companies, that is already sensitive. For law firms, it is far more serious. GDPR matters, just like Schrems II and professional secrecy and client scrutiny. Increasingly, security reviews are not limited to encryption and certifications. They now reach into:

• the legal structure of the provider;
• the ownership of the platform;
• the potential reach of foreign law and;
• the practical question of who could demand access under circumstances the firm does not control.

Even when a platform is broadly compliant, it can still create procurement friction and extra client due diligence. But also, more internal review cycles, and tougher questions from regulated clients. Public sector work, financial institutions, cross-border matters, and sensitive investigations all increase the pressure.

Legal and reputational exposure lands first with the firm

There is a second point many firms underestimate. Under GDPR, the law firm remains the controller. The vendor may be the processor, but the legal and reputational exposure lands first with the firm. If there is a breach, a transfer issue, a challenge from a client, or a problem with explainability in AI processing, the firm cannot hide behind a vendor certification. It must explain why things like the architecture, data flow and the vendor choice were defensible in the first place.
That is what makes this a governance and a board-level risk question. In some cases, even a market-positioning question. Because once clients become more demanding and regulation keeps tightening, the difference between “probably compliant” and “strategically sound” becomes very real.

The stakes rise further when AI gets layered into the platform. A DMS with embedded AI may sound progressive, but it also forces harder questions.

• Where does inference happen?
• Is client data used for model improvement?
• How are permissions preserved?
• What gets logged?
• Which platform layer handles the interaction?
• How much of that remains inside the environment the firm already governs, and how much moves through a stack controlled elsewhere?

A Microsoft-native approach starts to look materially different, especially for firms already committed to Microsoft 365, Entra, Purview, and Copilot. When documents, identity, retention, audit, security, and AI architecture all live in the same environment, there is less fragmentation and far less legal fog. The firm builds on infrastructure it already owns and controls, rather than inserting another platform layer it will later need to defend to clients, compliance, and auditors.

That is what makes a SharePoint-native legal platform like Epona structurally different from a closed SaaS DMS. Why? Because it creates a different compliance and control profile. In a closed platform, the firm is not just buying functionality. It is also accepting a roadmap, a legal interpretation of compliance, and a deeper form of platform dependency. In a Microsoft-native model, the data environment remains the firm’s, and Epona adds the legal layer without locking the firm into a proprietary data structure.

That may not feel dramatic in a demo but it becomes very dramatic in audits, AI governance, strategic flexibility, and client due diligence. So which question should no law firm forget to ask when selecting a DMS?

Not “How polished is the experience today?”

The more important question is “Where does my data really live, under whose legal reach does it fall, and how much control do I still have tomorrow?”

It is not a sexy question. It is the one more firms should have asked much earlier.